Skip to content

Commit b510582

Browse files
committed
Add new blog article: MFA isn't an add-on
- New article explaining why MFA should be built-in, not sold separately - Covers FortiToken alternatives and Defguard's unified approach - Includes hero image and supporting graphics (ACL overview, Prusa architecture) - Full SEO optimization with JSON-LD schema and FAQ section - Internal links to NIS2 article, documentation, and product pages
1 parent d48c811 commit b510582

File tree

4 files changed

+212
-0
lines changed

4 files changed

+212
-0
lines changed
91 KB
Loading
17.4 KB
Loading
2.31 MB
Loading
Lines changed: 212 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,212 @@
1+
---
2+
title: "Security shouldn't cost extra — MFA isn't an add-on"
3+
publishDate: 2025-11-05
4+
description: "MFA is mandatory under frameworks like NIS2. See why legacy VPNs sell it as an add-on, how that creates cost and risk, and how Defguard builds it in by default."
5+
author: "Robert (Co-Founder, Defguard)"
6+
image: "/images/blog/mfa-isnt-an-addon/mfa-hero.png"
7+
---
8+
9+
![Security shouldn't cost extra — MFA isn't an add-on](/images/blog/mfa-isnt-an-addon/mfa-hero.png)
10+
11+
## Table of Contents
12+
- [The Hidden "Security Tax": The True Cost of a Fragmented Model](#the-hidden-security-tax-the-true-cost-of-a-fragmented-model)
13+
- [Security by Design: The FortiToken Alternative](#security-by-design-the-fortitoken-alternative)
14+
- [Defguard in Practice: The Prusa Research Case](#defguard-in-practice-the-prusa-research-case)
15+
- [The Real Choice: A Fragmented Model vs. A Unified Foundation](#the-real-choice-a-fragmented-model-vs-a-unified-foundation)
16+
- [Frequently Asked Questions (FAQ)](#frequently-asked-questions-faq)
17+
18+
To comply with standards like [NIS2](/blog/mfa-wireguard-nis2-compliance), Multi-Factor Authentication (MFA) has become a baseline requirement, not an option.
19+
20+
Yet in most enterprise VPNs, fundamentals such as MFA, SSO, and identity management are still treated as extras; not for technical reasons, but because separating them is profitable.
21+
22+
The result is predictable: organizations end up buying their security in fragments just to meet compliance. This leads to increased Total Operating Costs and time lost on stitching MFA and VPN together.
23+
24+
The problem isn't technical; it's commercial. Vendors have learned to turn essential protection into a series of recurring upgrades.
25+
26+
This article breaks down how that model works — and how Defguard was designed to solve it.
27+
28+
## The Hidden "Security Tax": The True Cost of a Fragmented Model
29+
30+
When basic security requirement is sold as a separate product, expenses rise fast — not just in licensing, but in complexity and risk.
31+
32+
### 1. The Licensing Cost
33+
34+
The "security tax" is unpredictable. The appliance price looks reasonable, but then you must add per-user MFA tokens and SSO or identity module licenses. The cost keeps scaling with your headcount, not your security.
35+
36+
### 2. The Operational Cost
37+
38+
This is the pain system admins feel. Every add-on, like separate MFA modules or token licenses, adds more components to configure, maintain, and update. Each new piece introduces another integration point, another dependency, and another potential failure.
39+
40+
**Our Fix:**
41+
42+
Defguard runs as a single, unified platform, ready to deploy in minutes and built to integrate with your existing environment.
43+
44+
From one admin panel, you can manage users, groups, devices, and MFA settings, define access policies, and monitor connections, all without switching between tools.
45+
46+
![Defguard Admin Dashboard — users, groups, devices, MFA settings, and access policies overview](/images/blog/mfa-isnt-an-addon/defguard-acl-overview.png)
47+
*All security layers in one place — users, devices, MFA policies, and access rules.*
48+
49+
### 3. When Security Becomes Optional
50+
51+
The real risk? Because MFA is a separate purchase, some departments may skip it to save budget. That creates inconsistent protection — the exact kind of compliance gap auditors find and attackers exploit.
52+
53+
**Our Fix:**
54+
55+
In Defguard, MFA isn't a license you can skip, it's part of the core platform. You cannot have a compliance gap when the secure baseline is the only baseline.
56+
## Security by Design: The FortiToken Alternative
57+
58+
We believe the legacy model is broken. Security isn't something you add — it's something you build on.
59+
60+
A modern VPN shouldn't upsell you MFA; it should deliver it by design. That's the principle behind Defguard.
61+
62+
### How We Do It: A Unified Platform
63+
64+
Defguard is a self-hosted, unified solution where identity and access control are part of the same architecture. Here's what that means in practice:
65+
66+
#### 1. Built-in User Management (IdP)
67+
68+
Defguard includes a native user database (often called an Identity Provider or IdP) as a core service.
69+
70+
This is where you manage your users and groups directly — no premium extensions or add-ons. [Learn how Defguard works as an SSO provider](https://docs.defguard.net/admin-and-features/openid-connect) for your organization.
71+
72+
#### 2. Built-in Multi-Factor Authentication (MFA)
73+
74+
Defguard also handles MFA as a core service, supporting standard time-based one-time passwords (TOTP) from authenticator apps such as Google Authenticator or Microsoft Authenticator — no proprietary tokens required. [Explore Defguard's built-in MFA](https://defguard.net/features/mfa).
75+
76+
#### 3. Integration with Your Existing Tools
77+
78+
For organizations already using external identity systems like Microsoft Entra ID, Google Workspace, Okta, or JumpCloud, Defguard provides native integration.
79+
80+
It uses the standard OpenID Connect (OIDC) protocol to securely connect to systems like Microsoft Entra ID, Google Workspace, Okta, or JumpCloud, letting users log in with their existing accounts. You can [see detailed SSO integration examples in our documentation](https://docs.defguard.net/admin-and-features/external-openid-providers).
81+
82+
![Defguard unified architecture — distributed locations overview](/images/blog/mfa-isnt-an-addon/defguard-prusa-location.png)
83+
*Unified architecture — one core, one proxy, multiple locations.*
84+
85+
### The Proof: It's in Our Open Source Plan
86+
87+
These security capabilities are not tiered upsells.
88+
89+
The ultimate proof is in our design: our Open Source plan includes both the built-in user database (IdP) and connection-level MFA from the start.
90+
91+
This is the difference between a system built for upsell and one built for security.
92+
## Defguard in Practice: The Prusa Research Case
93+
94+
This isn't theoretical. **Prusa Research** needed to scale their VPN for over 500 users, including production-floor devices and remote employees.
95+
96+
A fragmented model would have forced them to manage hundreds of separate token licenses and deal with complex identity integrations.
97+
98+
This was not a scalable or efficient solution.
99+
100+
**How we solved their problem:**
101+
102+
They chose Defguard because it's a single, unified platform. Because MFA is built-in, there are no token licenses to manage. Their IT team can provision a new user with MFA enabled in seconds, all from one place. When a user connects, Defguard enforces MFA as part of the connection process itself.
103+
104+
**The outcome is simple:**
105+
106+
100% of their VPN users have MFA enabled, because MFA isn't a license you can skip, it's part of the core platform.
107+
## The Real Choice: A Fragmented Model vs. A Unified Foundation
108+
109+
The problem with the legacy model is clear: you are forced to pay an enormous extra cost for MFA just to be compliant.
110+
111+
This isn't an accident. It's the result of a business model designed to sell you security in separate, expensive pieces.
112+
113+
Legacy VPNs treat security as a catalog of features; Defguard treats it as a foundation.
114+
115+
If you're facing another license renewal and see a "security tax" on your invoice, maybe it's time to move from a fragmented solution to a foundational one.
116+
117+
**See what built-in security looks like.**
118+
119+
[Book a Demo](/book-a-demo) and explore Defguard's modern VPN with MFA included.
120+
## Frequently Asked Questions (FAQ)
121+
122+
**How much does Fortinet MFA cost?**
123+
124+
Fortinet's MFA isn't a single price. It often requires separate purchases like FortiToken (for MFA) and FortiAuthenticator (for identity).
125+
126+
These components are necessary for compliance and make the true TCO much higher than the base price — [see FortiToken licensing details](https://www.fortinet.com/products/fortitoken).
127+
128+
**Is FortiToken required for Fortinet VPN MFA?**
129+
130+
Yes. In most FortiGate VPN configurations, FortiToken is the required component to enable MFA — as hardware or mobile tokens, licensed per user ([setup guide](https://docs.fortinet.com/document/fortigate/latest/administration-guide/fortitoken)).
131+
132+
**What is a good FortiToken alternative?**
133+
134+
A modern alternative to token-based MFA systems. Defguard includes Multi-Factor Authentication as a built-in feature — supporting standard TOTP codes from authenticator apps (like Google Authenticator) and a native user database (IdP) in every deployment. [Learn more about Defguard VPN with built-in MFA](https://defguard.net/features/mfa).
135+
136+
**Are there VPNs with MFA included in the base price?**
137+
138+
Yes. Defguard, as a modern WireGuard®-based platform, includes MFA by default — built into every deployment, with no extra licensing or modules.
139+
<script type="application/ld+json" is:inline>
140+
{`{
141+
"@context": "https://schema.org",
142+
"@graph": [
143+
{
144+
"@type": "BlogPosting",
145+
"headline": "Security shouldn't cost extra — MFA isn't an add-on",
146+
"description": "MFA is mandatory under frameworks like NIS2. Learn why legacy VPNs sell it as an add-on and how Defguard builds it in by default.",
147+
"image": "https://defguard.net/images/blog/mfa-isnt-an-addon/mfa-hero.png",
148+
"author": {
149+
"@type": "Person",
150+
"name": "Robert",
151+
"jobTitle": "Co-Founder",
152+
"affiliation": {
153+
"@type": "Organization",
154+
"name": "Defguard"
155+
}
156+
},
157+
"publisher": {
158+
"@type": "Organization",
159+
"name": "Defguard",
160+
"logo": {
161+
"@type": "ImageObject",
162+
"url": "https://defguard.net/svg/logo-full.svg"
163+
}
164+
},
165+
"datePublished": "2025-11-05",
166+
"mainEntityOfPage": {
167+
"@type": "WebPage",
168+
"@id": "https://defguard.net/blog/mfa-isnt-an-addon/"
169+
},
170+
"articleSection": "Security, VPN, MFA, WireGuard",
171+
"keywords": ["MFA", "FortiToken", "WireGuard", "NIS2", "VPN", "Defguard", "SSO", "IdP"]
172+
},
173+
{
174+
"@type": "FAQPage",
175+
"mainEntity": [
176+
{
177+
"@type": "Question",
178+
"name": "How much does Fortinet MFA cost?",
179+
"acceptedAnswer": {
180+
"@type": "Answer",
181+
"text": "Fortinet's MFA isn't a single price. It often requires separate purchases like FortiToken (for MFA) and FortiAuthenticator (for identity). These components are necessary for compliance and make the true TCO much higher than the base price."
182+
}
183+
},
184+
{
185+
"@type": "Question",
186+
"name": "Is FortiToken required for Fortinet VPN MFA?",
187+
"acceptedAnswer": {
188+
"@type": "Answer",
189+
"text": "Yes. In most FortiGate VPN configurations, FortiToken is the required component to enable MFA — as hardware or mobile tokens, licensed per user."
190+
}
191+
},
192+
{
193+
"@type": "Question",
194+
"name": "What is a good FortiToken alternative?",
195+
"acceptedAnswer": {
196+
"@type": "Answer",
197+
"text": "A modern alternative to token-based MFA systems. Defguard includes Multi-Factor Authentication as a built-in feature — supporting standard TOTP codes from authenticator apps (like Google Authenticator) and a native user database (IdP) in every deployment. There's no need for separate hardware or mobile tokens."
198+
}
199+
},
200+
{
201+
"@type": "Question",
202+
"name": "Are there VPNs with MFA included in the base price?",
203+
"acceptedAnswer": {
204+
"@type": "Answer",
205+
"text": "Yes. Defguard, as a modern WireGuard®-based platform, includes MFA by default — built into every deployment, with no extra licensing or modules."
206+
}
207+
}
208+
]
209+
}
210+
]
211+
}`}
212+
</script>

0 commit comments

Comments
 (0)